Account takeover happens when an attacker gains control of a legitimate customer, employee or seller account and then uses the trusted profile to make payments, change bank details, issue refunds or withdraw balances. Because the activity comes from a real account, ordinary transaction checks can miss it.
Credential reuse and phishing are common entry points
Attackers can obtain passwords through phishing, malware or credential stuffing using passwords leaked from another site.
Require strong passwords, rate-limit login attempts and use multi-factor authentication for sensitive accounts.
Use device and behavioural signals after login
A successful password does not prove the usual user is present. New devices, impossible travel, unusual IP addresses and sudden changes in purchase behaviour can indicate takeover.
Risk-based checks can trigger step-up authentication without challenging every normal login.
Saved cards make a compromised account more valuable
An attacker can buy goods without knowing the full card number if a saved credential is already available.
Require stronger confirmation for high-value purchases, new delivery addresses or unusual order patterns where risk warrants it.
Payout-account changes need independent protection
Marketplace sellers and business users can lose much more if an attacker changes the bank account receiving payouts.
Use MFA, re-authentication, cooling periods and alerts for payout-detail changes. One login should not silently redirect all future seller cash.
Tell users about sensitive changes
Send alerts for password reset, MFA change, new device, payout-account change and unusual payment where appropriate.
Give the legitimate user a fast route to freeze the account. Delay allows the attacker to change more recovery information.
Reset credentials and review every financial action
After takeover, invalidate sessions, rotate credentials and inspect purchases, refunds, beneficiary changes and payouts from the affected period.
Do not assume resetting the password fixes financial damage already scheduled in downstream payment systems.
Worked example: a marketplace seller's password is compromised. The attacker logs in from a new device, changes the payout account and waits until Friday's £40,000 payout. A cooling period and change alert can stop the redirection before money leaves even though the login itself succeeded.
Keep account-recovery controls stronger than normal login. An attacker who can reset MFA using a weak email-only process can bypass otherwise strong authentication.
Measure takeover loss separately from stolen-card fraud. The prevention tools overlap, but account takeover often involves identity, login and payout controls rather than only card authorisation.
Worked example: an attacker gains access to a business customer's ecommerce account containing a saved corporate card and changes the delivery address. The purchase can pass card checks because the credential is valid. A new-device alert, step-up authentication and unusual-shipping-address review can stop the fraud before fulfilment.
Protect email-change and phone-change events because attackers often modify recovery information before attempting financial actions. Send notifications to the old contact as well as the new one where practical.
For seller or creator platforms, payout-account takeover can be more valuable than buying goods. Apply the strongest controls to the moment the account changes where future cash is sent.
Keep a fraud recovery workflow that restores the legitimate user's account without erasing evidence. Session logs, payout changes and transaction history can be needed by the bank, insurer or police after access is returned.
Use risk-based holds on withdrawals or payouts after sensitive account changes. A genuine user can tolerate a short verification delay more easily than the business can recover a large transfer sent to an attacker-controlled account.
Review session-management security. Password reset should invalidate old sessions where appropriate, otherwise an attacker can remain logged in after the legitimate user changes credentials.
For high-value B2B accounts, notify an administrator when new users are invited or existing roles are elevated. An attacker who cannot change the payout account directly may first create a second administrator and then use that account to approve the change.
Review support-agent recovery powers. A well-meaning support employee should not be able to remove MFA or change a payout email after answering weak knowledge-based questions that an attacker can research publicly.
Correlate takeover signals across login, payment and support systems. A password reset followed by a new device, delivery-address change and high-value purchase within ten minutes is more suspicious than any single event alone.
Use separate alerts for privilege escalation. A compromised ordinary user account can be the first step toward administrator access, so changes in role or permissions should be monitored with the same seriousness as payout changes.
Keep customer support from revealing account-security details that help attackers. Staff should verify identity before discussing saved cards, recent payout values or recovery channels.
Review high-risk accounts more frequently after recovery. A compromised mailbox, device or password manager can expose the user again even after one account reset, so temporary enhanced monitoring can reduce repeat loss.
Editorial Verdict
Account takeover turns a trusted profile into a fraud tool.
Protect login, sensitive changes and saved-payment actions separately, and review all financial events after compromise. A legitimate username should never be treated as sufficient evidence for an unusual money movement.
Sources
- National Cyber Security Centre, password and authentication guidance: https://www.ncsc.gov.uk/collection/passwords
- National Cyber Security Centre, phishing guidance: https://www.ncsc.gov.uk/guidance/phishing
- FCA, Strong Customer Authentication: https://www.fca.org.uk/firms/strong-customer-authentication